CVE-2025-58034
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests or CLI commands.
- Affected products
- Fortiweb
- Fortinet Fortiweb
- < 7.0.12, 7.2.12, 7.4.11, 7.6.6, 8.0.2
- CVSS 3.1
- 7.2 HIGH
- EPSS
- 55.6% (99th percentile)
- Weakness
- CWE-78
- NVD status
- Analyzed
- Published
- 2025-11-18
Fix
Upgrade to FortiWeb version 8.0.2 or above Upgrade to FortiWeb version 7.6.6 or above Upgrade to FortiWeb version 7.4.11 or above Upgrade to FortiWeb version 7.2.12 or above Upgrade to FortiWeb version 7.0.12 or above
CVE-2025-58034 at NVD
9 known exploits for CVE-2025-58034
Proof-of-concept code and exploit modules indexed by Sploitus
Exploit for OS Command Injection in Fortinet Fortiweb
FortiGate-FortiWeb-Multi-Exploit-Extractor
Exploit for OS Command Injection in Fortinet Fortiweb
Exploit for OS Command Injection in Fortinet Fortiweb
Fortinet FortiWeb unauthenticated RCE
π Fortinet FortiWeb Unauthenticated Remote Code Execution
Exploit for CVE-2025-50834
Exploit for OS Command Injection in Fortinet Fortiweb
Exploit for CVE-2025-58034